Blackoutware is a ransomware-as-a-service (RaaS) operation that was first observed in late 2023. It functions as a financially motivated cybercrime group, deploying ransomware that encrypts user files and threatens data exfiltration to coerce victims into paying a ransom. The group is distinguished by its use of the '.blo' extension for encrypted files and a specific ransom note titled '!!! WARNING!!!.txt'. It operates under a double-extortion model, combining file encryption with the threat of public data leakage if demands are not met.
Tecnicas MITRE
T1486 - Data Encrypted for Impact, T1490 - Inhibit System Recovery, T1567 - Exfiltration Over Web Service
Tipo
ransomware
Pais origen
null
Motivacion
-
Impacto
38
Actualizado
Fri, 19 Ju
Paises objetivo (SOCRadar)
AustraliaCanadaGermanySpainFranceUnited KingdomCroatiaItalyJapanKorea, Republic of
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingManufacturingConstructionPublic AdministrationEducational ServicesWholesale TradeEnergy & Utilities Accommodation&Food ServicesNational Security&International Affairs